CVE-2026-2457: WebSocket Message Spoofing via Permalink Embed Manipulation
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-supplied post metadata which allows an authenticated attacker to spoof permalink embeds impersonating other users via crafted PUT requests to the post update API endpoint.. Mattermost Advisory ID: MMSA-2025-00569
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2457?
CVE-2026-2457 is rated as a medium severity vulnerability.
How do I fix CVE-2026-2457?
To fix CVE-2026-2457, update Mattermost to versions 11.3.1 or later, 11.2.3 or later, or 10.11.11 or later.
Who is affected by CVE-2026-2457?
CVE-2026-2457 affects Mattermost versions 11.3.0 and prior, 11.2.2 and prior, and 10.11.10 and prior.
What type of attack is possible with CVE-2026-2457?
CVE-2026-2457 allows an authenticated attacker to spoof permalink embeds and impersonate other users.
What are the common symptoms of exploitation of CVE-2026-2457?
Common symptoms of exploitation include unexpected user impersonation and incorrect messages appearing in chats.